Security restrictions bypass in Network Time Protocol - CVE-2018-7170
Published: March 1, 2018 / Updated: March 1, 2018
Vulnerability identifier: #VU10801
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7170
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to bypass security restrictions on the target system.
The weakness exists due to insufficient security restrictions. A remote attacker can create multiple crafted ephemeral associations to bypass security restrictions and modify the clock.
The weakness exists due to insufficient security restrictions. A remote attacker can create multiple crafted ephemeral associations to bypass security restrictions and modify the clock.
Affected software
Network Time Protocol
Amazon Linux AMI
Gentoo Linux
Arch Linux
IBM AIX
FreeBSD
Slackware Linux
Opensuse
Fedora
ntp
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
Flex System FC3171 8Gb SAN Switch
Flex System FC3171 8Gb SAN Pass-thru
Amazon Linux AMI
Gentoo Linux
Arch Linux
IBM AIX
FreeBSD
Slackware Linux
Opensuse
Fedora
ntp
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
Flex System FC3171 8Gb SAN Switch
Flex System FC3171 8Gb SAN Pass-thru
How to mitigate CVE-2018-7170
Update to version 4.2.8p11.
ntp - addressed in versions 4.2.8p11-1.fc26, 4.2.8p11-1.fc27, 4.2.8p12-1.fc27, 4.2.8p12-1.fc28
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.45.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.14.02.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.14.02.00
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.45.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.14.02.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.14.02.00
External References
Related Security Bulletins
- Multiple vulnerabilities in Network Time Protocol
- Slackware Linux update for ntp
- FreeBSD update for ntpd
- Arch Linux update for ntp
- Amazon Linux AMI update for ntp
- Gentoo update for NTP
- Multiple vulnerabilities in IBM AIX
- Amazon Linux AMI update for ntp
- OpenSUSE Linux update for ntp
- Multiple vulnerabilities in IBM AIX
- Multiple vulnerabilities in QLogic 8Gb Intelligent Pass-thru Module and SAN Switch Module for IBM BladeCenter and IBM Flex System FC3171 8Gb SAN Switch & SAN Pass-thru
- Fedora 27 update for ntp
- Fedora 26 update for ntp
- Fedora 27 update for ntp
- Fedora 28 update for ntp